Daily Digest

CISA Updates OSS Guidance; Ransomware Groups Active; Critical Vulnerabilities Patched

CISA Updates OSS Guidance; Ransomware Groups Active; Critical Vulnerabilities Patched

August 2, 2026
11 articles (8 new, 3 updated)
33 min read

Summary

This daily summary highlights key cybersecurity developments, including significant updates from CISA and new vulnerability disclosures. CISA has released enhanced guidance for securing open-source software (OSS), introducing the 'C4 Framework' for assessing OSS project trustworthiness and encouraging a 'default open source' approach for federal agencies. The agency also clarified that AI systems are only considered open source for risk management if their training data and models are fully transparent.

In response to ongoing threats, CISA and the FBI have attributed recent cyberattacks on U.S. water systems to Iran-linked actors, specifically mentioning groups like CyberAv3ngers. These attacks target internet-exposed Rockwell Automation PLCs, causing operational disruptions. Microsoft has also provided further details on the 'CaptiveCrunch' campaign, attributing it to Midnight Blizzard and detailing the use of a new infostealer, ChocoShell, and advanced techniques targeting hotel Wi-Fi networks.

Several critical vulnerabilities have been patched this period. N-able is warning of active exploitation of CVE-2026-18556, an authentication bypass flaw in N-central RMM software, urging immediate upgrades. Adobe has addressed a critical CVSS 10.0 RCE flaw (CVE-2026-48449) in Adobe Campaign Classic, alongside a high-severity SQL injection flaw. Ruby on Rails has also patched a critical RCE flaw (CVE-2026-66066) in its Active Storage component.

Ransomware activity remains a concern, with multiple groups claiming breaches. CRPxO ransomware has listed Encore Enterprises, 'thegentlemen' has targeted Philippine Savings Bank, Play ransomware has added three U.S. companies to its leak site, 'incransom' claims a breach of quantum firm Quantinuum, and 'Global Secret Group' has targeted a Texas mental health practice. Defenders should review their OSS security posture, patch critical vulnerabilities promptly, and remain vigilant against evolving ransomware tactics.

Filter by Category

New Articles (8)

Updated Articles (3)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.